{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0438",
  "aliases": [
    "CVE-2026-0628",
    "CVE-2026-55945"
  ],
  "published": "2026-09-16T00:00:00Z",
  "firstReported": {
    "date": "2026-09-16",
    "url": "https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants/",
    "publisher": "Forever Security"
  },
  "modified": "2026-09-25T00:00:00Z",
  "summary": "Exposed files, browsing data or browser actions on instructions from a malicious extension: the built-in agents in Chrome, Edge, Opera Neon, Perplexity Comet and Claude in Chrome, in normal browsing.",
  "details": "## What\n\nForever Security and BleepingComputer reported five browser-agent demonstrations under the BragJack name. A malicious extension could cause the built-in assistants to read local or browser data, take screenshots or act on websites; Chrome and Edge assigned CVE identifiers.\n\n## Detection\n\nThe researchers demonstrated the behavior across five browser agents.\n\n## Fix\n\nKeep browsers and agent extensions updated, remove untrusted extensions and avoid granting broad extension permissions.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "chrome-gemini"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "edge-copilot"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "opera-neon"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "perplexity-comet"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    },
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "claude-in-chrome"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "REPORT",
      "url": "https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants/"
    },
    {
      "type": "ARTICLE",
      "url": "https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/"
    }
  ],
  "database_specific": {
    "severity": "HIGH",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "tool-poisoning",
        "data-exfiltration",
        "over-privileged-combination"
      ],
      "cwe": [
        "CWE-693"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI01",
          "ASI04",
          "ASI02"
        ],
        "atlas": [
          "AML.T0051.001",
          "AML.T0112.000"
        ]
      },
      "cveBoundary": "exposed-surface",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants/",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Update the affected browsers and remove untrusted extensions.",
        "actions": [
          {
            "type": "reconfigure",
            "target": "browser.extensions",
            "to": "remove untrusted extensions and restrict permissions",
            "why": "The reports identify malicious extensions as the common input to the browser agents.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "Chrome Gemini, Edge Copilot, Opera Neon, Perplexity Comet or Claude in Chrome with the built-in agent enabled",
          "any": false,
          "status": "confirmed",
          "source": "https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants/"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any ordinary browsing task handled by the built-in browser agent",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "Browser extensions and the built-in browser-agent capabilities",
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/"
        },
        "approval": {
          "value": "The demonstrated agents used their existing browser privileges to read data or take actions",
          "mode": "none-required",
          "status": "detected",
          "source": "https://forever.security/blog/bragjack-hijacking-5-browsers-via-built-in-ai-assistants/"
        },
        "inputControl": "tool-provider",
        "agentAction": "The browser agent reads local or browser data, takes screenshots or acts on websites under extension-controlled instructions.",
        "harm": "data-exfiltration",
        "divergence": "none",
        "reach": {
          "value": "Browser data, local files and websites available to the browser",
          "kinds": [
            "project-files",
            "browser-session",
            "network"
          ],
          "status": "confirmed",
          "source": "https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/"
        }
      },
      "claims": [
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2026-0628",
          "value": "CVE-2026-0628",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-0628",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:24Z"
        },
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2026-55945",
          "value": "CVE-2026-55945",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-55945",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:24Z"
        },
        {
          "kind": "severity",
          "statement": "Severity HIGH; matches ADP/NVD",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-0628",
          "observed": "ADP/NVD: HIGH 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H); CNA: MODERATE 4.2 (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C); OSV: HIGH 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)",
          "result": "match",
          "method": "machine",
          "checkedAt": "2026-09-24T19:33:24Z"
        }
      ],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
